live inventory

Agent & model inventory

Governance starts with a map you did not draw by hand. VisIQ maintains a live inventory of the custom agents, frameworks, MCP servers, and local models on your estate, fed by endpoint discovery rather than a questionnaire, and it states each project's governance coverage plainly: governed, harnessed, or ungoverned.

No. 01 · Agent & model inventorylive inventory

Why the map comes before the policy

Most organizations try to govern AI with a partial map. Teams add agent frameworks to active repos, developers run local models on workstations, and MCP servers appear in editor configs. None of it waits for review, so a register built from interviews is stale before it circulates.

Policy-first programs stall on exactly this. You cannot decide which systems matter most, or where the highest-risk gaps sit, without a credible inventory underneath the question. Discovery has to run continuously, because the estate changes faster than any survey.

No. 02 · Agent & model inventorylive inventory

Where the entries come from

The inventory is fed by the same endpoint sensor that powers shadow AI discovery, which reads installed packages, editor configuration, and running services for agentic signals. A detection the platform already knows is matched to its registered agent; an unrecognized one opens as a finding, tied to the host and code project where it surfaced.

Provider keys get more careful handling. The sensor keeps only a fingerprint of a key-shaped string, so the plaintext never leaves the endpoint, and the inventory records the match as a lead to run down; a fingerprint alone does not prove a live credential. And because the sensor only reads, populating the map changes nothing about how any agent runs.

No. 03 · Agent & model inventorylive inventory

How a project earns its coverage badge

Discovery walks each code project and badges every one that carries an agent framework. Ungoverned means agentic code with no installed VisIQ harness, and listing the harness in a manifest does not move the badge; a declared dependency has never blocked a tool call. Harnessed means the harness is installed but quiet; governed means a registered agent on that host is live.

A scan cut short by a budget or deadline never auto-resolves a finding, and a degraded scan is surfaced as degraded. A hole in the map that reads as a clean result is the most dangerous kind of gap. "Couldn't see" is never "safe."

No. 04 · Agent & model inventorylive inventory

From finding to governed agent

A finding has three exits. You register it, which brings the agent under governance; you mark it as something the team runs on purpose; or you open an investigation. Registration starts the agent in monitor mode, so its behavior is on the record before any rule is allowed to block it.

The inventory is where enforcement gets its facts. Business functions are inferred from observed traffic, thin spots in coverage come with a suggested control to close them, and the same map answers the board's first question: what custom AI is actually running here?